[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGkgSTCCXKC5tShGH_n_5OfulvgXcvfqbt3urUcrpBzQ":3,"$f0dtgPfgau-voz3SKRTBA2evUfPhyA8DjTKk82XoSzfQ":139,"$fJPqYBD3SL7vlRt4EEgyevhnlkFtQwo7Pboz3Kopmj3U":144},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":18,"download_link":25,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":35,"analysis":26,"fingerprints":26},"ganava-location-access-control","Ganava Location Access Control","1.0.0","sandipganava","https:\u002F\u002Fprofiles.wordpress.org\u002Fsandipganava\u002F","\u003Cp>\u003Cstrong>Ganava Location Access Control\u003C\u002Fstrong> is a premium-grade, lightweight security tool designed to give you total control over who visits your WordPress site. Whether you need to block specific regions for compliance, redirect users to localized pages, or protect your store from high-risk countries, this plugin provides the tools you need with a modern, intuitive interface.\u003C\u002Fp>\n\u003Cp>Built with performance in mind, it integrates natively with \u003Cstrong>Cloudflare Geolocation\u003C\u002Fstrong> headers for zero-latency detection, falling back to reliable GeoIP services when needed.\u003C\u002Fp>\n\u003Ch3>Key Benefits\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Precision Targeting\u003C\u002Fstrong>: Don’t just block countries; target specific regions or cities for granular control.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Modern UI\u003C\u002Fstrong>: Manage your rules using a fast, React-powered administration dashboard.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO Friendly\u003C\u002Fstrong>: Built-in bot detection ensures that search engines like Google and Bing can still crawl your site while malicious traffic is blocked.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce Ready\u003C\u002Fstrong>: Restrict product availability based on the shopper’s location.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Rule Management\u003C\u002Fstrong>: Create unlimited geo rules with priority ordering.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Targeting Modes\u003C\u002Fstrong>:\n\u003Cul>\n\u003Cli>Target specific pages, posts, or categories.\u003C\u002Fli>\n\u003Cli>Entire site protection (Global Blocking).\u003C\u002Fli>\n\u003Cli>URL path matching with wildcard support.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Geographic Criteria\u003C\u002Fstrong>: Block or allow based on Country, Region, or City.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Connection Filtering\u003C\u002Fstrong>: Detect and block VPN, Proxy, or Tor traffic (requires API key).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multiple Actions\u003C\u002Fstrong>:\n\u003Cul>\n\u003Cli>\u003Cstrong>Block\u003C\u002Fstrong>: Show a 403 Access Denied status.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Redirect\u003C\u002Fstrong>: Send users to a custom URL (perfect for localized marketing).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Message\u003C\u002Fstrong>: Show a beautiful HTML message or a dedicated WordPress page.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Audit Logging\u003C\u002Fstrong>: Track every block event with detailed visitor data (IP, Country, Time).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Developer Friendly\u003C\u002Fstrong>: Hooks and filters to extend functionality.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin utilizes external services to provide accurate geolocation data and threat detection capabilities (VPN\u002FProxy\u002FTor detection). These services are only queried when necessary (e.g. if the user’s IP address cannot be resolved locally or via Cloudflare headers).\u003C\u002Fp>\n\u003Col>\n\u003Cli>\n\u003Cp>\u003Cstrong>ProxyCheck.io\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Used for high-accuracy geolocation and detecting whether a visitor is using a VPN, Proxy, or Tor network.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent\u003C\u002Fstrong>: The visitor’s IP address is sent to ProxyCheck.io upon request processing.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Links\u003C\u002Fstrong>: \u003Ca href=\"https:\u002F\u002Fproxycheck.io\u002Fterms\u002F\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fproxycheck.io\u002Fprivacy\u002F\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>ip-api.com\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: Used as a fallback service for basic geolocation (Country, Region, City) if ProxyCheck.io is unavailable or unconfigured.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent\u003C\u002Fstrong>: The visitor’s IP address is sent to ip-api.com.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Links\u003C\u002Fstrong>: \u003Ca href=\"https:\u002F\u002Fip-api.com\u002Fdocs\u002Flegal\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fip-api.com\u002Fdocs\u002Flegal\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Fol>\n","Control your site access globally with precision. Block or redirect visitors based on their country, region, or city using Cloudflare headers or high- &hellip;",0,115,100,1,"2026-05-22T10:51:00.000Z","6.9.5","5.8","",[20,21,22,23,24],"blocking","cloudflare","geo","redirect","security","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fganava-location-access-control.1.0.0.zip",null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":11,"avg_security_score":13,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},2,30,94,"2026-08-25T11:28:46.462Z",[36,58,81,99,121],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":44,"downloaded":45,"rating":13,"num_ratings":46,"last_updated":47,"tested_up_to":16,"requires_at_least":48,"requires_php":49,"tags":50,"homepage":54,"download_link":55,"security_score":56,"vuln_count":14,"unpatched_count":11,"last_vuln_date":57,"fetched_at":27},"advanced-country-blocker","Advanced Country Blocker","2.3.2","brstefanovic","https:\u002F\u002Fprofiles.wordpress.org\u002Fbrstefanovic\u002F","\u003Cp>\u003Cstrong>Advanced Country Blocker\u003C\u002Fstrong> helps you secure your WordPress site by restricting access based on the visitor’s geolocation (country) or IP address. Upon activation, the plugin detects the activating admin’s country and automatically sets that as the only allowed country. All other visitors from different countries are blocked, unless they use a secret key parameter to temporarily whitelist their IP. Country detection uses the privacy-friendly ip-api.com service by default but can be switched to a fully offline MaxMind GeoLite2 (or compatible) database file once you configure a local copy.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Automatically allows the admin’s country\u003C\u002Fstrong> on plugin activation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Flexible IP-to-country lookups\u003C\u002Fstrong> – start with the built-in ip-api.com integration and optionally switch to an offline MaxMind GeoLite2 Country (or compatible) \u003Ccode>.mmdb\u003C\u002Fcode> database file.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Allowlist or blacklist mode\u003C\u002Fstrong> – choose whether the country list acts as an allowlist or blocklist without re-entering countries.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Temporary access\u003C\u002Fstrong> via a customizable secret URL parameter (e.g., \u003Ccode>?MySecretKey=1\u003C\u002Fcode>).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CAPTCHA Challenge\u003C\u002Fstrong> – allow blocked visitors to solve a CAPTCHA to gain temporary access (supports Google reCAPTCHA v2\u002Fv3, hCaptcha, Cloudflare Turnstile).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-Time Activity Monitor\u003C\u002Fstrong> – live dashboard showing active visitors, recent blocks, and traffic statistics.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Analytics Dashboard\u003C\u002Fstrong> – comprehensive charts and statistics about blocked attempts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Manual blacklisting and safelisting of IPs\u003C\u002Fstrong> for added security and to accommodate uptime monitors.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Optional email alerts\u003C\u002Fstrong> when new visitors are blocked.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin bypass\u003C\u002Fstrong> so logged-in admins can always access the site (toggleable in the code).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Detailed logging\u003C\u002Fstrong> of blocked attempts in a custom database table, displayed in the WP admin.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom response controls\u003C\u002Fstrong> – personalise the block page title\u002Fmessage, choose the HTTP status (403, 410, 451) or redirect to any URL.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic log cleanup\u003C\u002Fstrong> with configurable retention plus a one-click “Clear Logs” button.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Use the plugin settings page (\u003Cstrong>Country Blocker\u003C\u002Fstrong> menu in WP admin) to configure the list of allowed countries, blacklisted countries, blacklisted IPs, and whether email alerts are enabled.\u003C\u002Fp>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This plugin is open-sourced software licensed under the \u003Ca href=\"https:\u002F\u002Fwww.gnu.org\u002Flicenses\u002Fgpl-3.0.html\" rel=\"nofollow ugc\">GPLv3 or later\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>By default this plugin contacts the ip-api.com geolocation service to detect visitor countries. You can disable all external lookups by switching the IP lookup method to the local MaxMind database in the settings.\u003C\u002Fp>\n","An advanced security plugin that blocks website visitors by country, with additional features like blacklisting, logging blocked attempts, admin bypas &hellip;",2000,14219,6,"2026-02-06T09:04:00.000Z","5.0","7.2",[20,51,52,53,24],"country","geolocation","ip-blocking","https:\u002F\u002Fsparkcan.com\u002Facb.html","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadvanced-country-blocker.2.3.2.zip",99,"2026-02-06 20:24:09",{"slug":59,"name":60,"version":61,"author":62,"author_profile":63,"description":64,"short_description":65,"active_installs":44,"downloaded":66,"rating":33,"num_ratings":67,"last_updated":68,"tested_up_to":69,"requires_at_least":70,"requires_php":71,"tags":72,"homepage":77,"download_link":78,"security_score":79,"vuln_count":14,"unpatched_count":11,"last_vuln_date":80,"fetched_at":27},"advanced-ip-blocker","Advanced IP Blocker","8.11.10","IniLerm","https:\u002F\u002Fprofiles.wordpress.org\u002Finilerm\u002F","\u003Cp>\u003Cstrong>Advanced IP Blocker\u003C\u002Fstrong> is your all-in-one security solution to safeguard your WordPress website from a wide range of threats. This plugin provides a comprehensive suite of tools to automatically detect and block malicious activity, including brute-force attacks, vulnerability scanning, and spam bots. With its intuitive interface, you can easily manage whitelists, blocklists, and view detailed security logs to understand exactly how your site is being protected.\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>\u003Cstrong>Important Note on PHP Version:\u003C\u002Fstrong>\u003Cbr \u002F>\n  To ensure maximum security and access to all features, we strongly recommend using \u003Cstrong>PHP 8.1 or higher\u003C\u002Fstrong>. Some advanced features (like the local MaxMind database or full 2FA management via WP-CLI) require PHP 8.1.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003Cbr \u002F>\n*   \u003Cstrong>(NEW) Block Ghost IPs:\u003C\u002Fstrong> Automatically block IPs without ASN and Reverse DNS to stop anonymous traffic (Warning: Could cause false positives if rDNS is misconfigured by ISPs).\u003Cbr \u002F>\n*   \u003Cstrong>(NEW) Captcha Integrations (Turnstile & hCaptcha):\u003C\u002Fstrong> Seamlessly integrate modern verification challenges like Cloudflare Turnstile and hCaptcha, with granular control per module and a smart fallback to our invisible JS Challenge to prevent accidental lockouts.\u003Cbr \u002F>\n*   \u003Cstrong>(NEW) Rate Limiting Advanced Rules:\u003C\u002Fstrong> Create highly specific rate limits for different endpoints. For example, set a strict limit with a Turnstile challenge for \u003Ccode>\u002Flogin\u003C\u002Fcode>, while keeping a more generous limit with a temporary block for your main API, all without affecting the rest of the site.\u003Cbr \u002F>\n*   \u003Cstrong>(NEW) Distributed Attack Protection (Auto-Panic):\u003C\u002Fstrong> Automatically shields your entire site with a global JS challenge during massive traffic spikes, keeping your server online while intelligently bypassing trusted bots and excluded routes.\u003Cbr \u002F>\n*   \u003Cstrong>IP & ASN Diagnostics Tool:\u003C\u002Fstrong> A complete Inspector tool integrated directly into the admin bar. Quickly audit any IP or ASN against your Geolocation database, Threat Scoring system, Spamhaus drops, and manual blocking rules in real-time.\u003Cbr \u002F>\n*   \u003Cstrong>Advanced Rules Import\u002FExport:\u003C\u002Fstrong> Seamlessly migrate or backup your complex custom security rules across multiple WordPress websites. With full JSON validation, structural deduplication, and “cost-zero” client-side file generation, agency users can clone their perfect firewall setups in seconds.\u003Cbr \u002F>\n*   \u003Cstrong>Granular JS Challenge Modes:\u003C\u002Fstrong> You can now choose exactly how the security challenge behaves. Select “Managed” for ultimate security requiring human interaction (a checkbox), or “Automatic” for an invisible, transparent Proof-of-Work execution that stops bots silently. Apply different modes per module!\u003Cbr \u002F>\n*   \u003Cstrong>Country Selector Copy\u002FPaste:\u003C\u002Fstrong> Say goodbye to manually selecting 50+ countries. You can now instantly copy and paste a raw list of 2-letter country codes directly into Geoblocking, Geo-Challenge, and Whitelist Login fields.\u003Cbr \u002F>\n*   \u003Cstrong>AIB Cloud Network V3:\u003C\u002Fstrong> Upgrade to the next-generation distributed threat intelligence network. The new API V3 provides secure, individual API Keys per site, drastically improving synchronization reliability, threat telemetry, and global network stability.\u003Cbr \u002F>\n*   \u003Cstrong>Whitelist Login Countries:\u003C\u002Fstrong> Take absolute control over administrative access. Easily restrict your WordPress login page and XML-RPC to only allow connections from specific, whitelisted countries, instantly blocking unauthorized foreign login attempts.\u003Cbr \u002F>\n*   \u003Cstrong>(IMPROVED) Bulk Import\u002FExport for Blocked IPs & Whitelist:\u003C\u002Fstrong> Seamlessly import massive lists of IPs via CSV or manual entry. The system now features a bulletproof “Bulk Import” type, strict duration inheritance, and intelligent conflict resolution.\u003Cbr \u002F>\n*   \u003Cstrong>Internal Security & Forensics:\u003C\u002Fstrong> A complete audit suite solely for WordPress. Track every sensitive event (plugin installs, settings changes, user logins) and monitor your critical files for unauthorized modifications with the integrated File Integrity Monitor.\u003Cbr \u002F>\n*   \u003Cstrong>Activity Audit Log:\u003C\u002Fstrong> Gain complete visibility into what’s happening on your site. Who deactivated a plugin? Who changed a setting? The Audit Log answers these questions with timestamped, immutable records.\u003Cbr \u002F>\n*   \u003Cstrong>Deep Scan Email Reports:\u003C\u002Fstrong> Get a weekly security summary delivered to your inbox, detailing pending updates, vulnerability status, and recent attack trends.\u003Cbr \u002F>\n*   \u003Cstrong>Username Blocking & Rules:\u003C\u002Fstrong> Gain granular control over login security. Creating Advanced Rules to block, challenge, or score specific usernames (e.g., “admin”, “test”).\u003Cbr \u002F>\n*   \u003Cstrong>Enhanced Lockdown Notifications:\u003C\u002Fstrong> Distributed Lockdowns (404\u002F403) now fully support Email and Push notifications, ensuring you never miss a critical security event.\u003Cbr \u002F>\n*   \u003Cstrong>Improved Logging:\u003C\u002Fstrong> New “Endpoint Challenge” event type provides deeper visibility into challenges served during automated lockdowns.\u003Cbr \u002F>\n*   \u003Cstrong>Server IP Reputation Check. Instantly audit your web server’s IP address against major blacklists (Spamhaus, AbuseIPDB) to diagnose SEO and email delivery issues.\u003Cbr \u002F>\n*   **HTTP Security Headers.\u003C\u002Fstrong> Easily configure essential security headers like HSTS, X-Frame-Options, and Permissions-Policy to harden your site against clickjacking, sniffing, and other browser-based attacks. Includes a “Report-Only” mode for CSP.\u003Cbr \u002F>\n*   \u003Cstrong>Site Health & Vulnerability Scanner. Audit your WordPress environment instantly. Detects outdated plugins, insecure PHP versions, and checks your installed plugins against a database of 30,000+ known vulnerabilities.\u003Cbr \u002F>\n*   **PERFORMANCE BOOST: High-Speed Community Database. Migrated the “Community Defense Network” blocklist to a dedicated, indexed database table. This allows checking thousands of malicious IPs in microseconds with zero impact on site memory usage.\u003Cbr \u002F>\n*   **Community Defense Network. Join forces with other WordPress admins. The plugin now shares anonymous attack data to build a global, real-time blocklist of verified threats. Protect your site with community-powered intelligence.\u003Cbr \u002F>\n*   **Auto-Cleaning Logic. Smart expiration handling ensures your blocklists stay fresh and performant, automatically removing stale IPs from both the database and external firewalls (Cloudflare\u002F.htaccess).\u003Cbr \u002F>\n*   **Cloud Edge Defense (Cloudflare). Connect your site directly to Cloudflare’s global network. Automatically sync your blocklists to the cloud to stop attackers before they reach your server. Zero server load protection.\u003Cbr \u002F>\n*   **Server-Level Firewall (.htaccess). Extreme performance upgrade. Write blocking rules and file hardening protections directly to your .htaccess file. Blocks threats instantly without loading PHP or WordPress.\u003Cbr \u002F>\n*   **IMPROVED: Smart Bot Verification. Enhanced logic to correctly identify legitimate traffic from iOS devices (iCloud Private Relay) and social media previews, eliminating false positives while keeping impostors out.\u003Cbr \u002F>\n*   **File Hardening.\u003C\u002Fstrong> Protect your most sensitive files (\u003Ccode>wp-config.php\u003C\u002Fcode>, \u003Ccode>readme.html\u003C\u002Fcode>, \u003Ccode>.git\u003C\u002Fcode>) at the server level with a single click.\u003Cbr \u002F>\n*   \u003Cstrong>AbuseIPDB Integration.\u003C\u002Fstrong> Proactively block attackers before they strike. The plugin can now check visitor IPs against AbuseIPDB’s real-time, crowdsourced database of malicious IPs and block those with a high abuse score on their very first request.\u003Cbr \u002F>\n*   \u003Cstrong>Edge Firewall Mode!\u003C\u002Fstrong> Protect any PHP file or standalone application within your WordPress directory (even if it’s not part of WordPress). Ideal for securing custom scripts, legacy applications, or folders like \u003Ccode>\u002Fscan\u002F\u003C\u002Fcode>. (Requires manual configuration).\u003Cbr \u002F>\n*   \u003Cstrong>Advanced Rules Engine!\u003C\u002Fstrong> Create powerful, custom security rules with multiple conditions (IP, Country, ASN, URI, User-Agent, Request Method, Referer) and actions (Block, Challenge, or add Threat Score).\u003Cbr \u002F>\n*   \u003Cstrong>Known Bot Verification.\u003C\u002Fstrong> A powerful new security layer that uses reverse DNS lookups to verify legitimate crawlers like Googlebot and Bingbot. This completely neutralizes attackers who try to bypass security rules by faking their User-Agent, assigning high threat scores to impostors.\u003Cbr \u002F>\n*   \u003Cstrong>Verify Monitoring Bots (IP List).\u003C\u002Fstrong> A brand new feature that downloads and caches official IP lists from popular uptime monitoring services (like UptimeRobot and Pingdom) to ensure they are never incorrectly blocked or challenged.\u003Cbr \u002F>\n*   \u003Cstrong>Onboarding Setup Wizard.\u003C\u002Fstrong> A brand new step-by-step wizard that guides new users through the essential security configurations (IP whitelisting, WAF, and bot traps) in under a minute, ensuring a strong security posture from day one.\u003Cbr \u002F>\n*   \u003Cstrong>Major Refactor: Codebase Modernization.\u003C\u002Fstrong> The entire plugin architecture has been refactored into a modern, modular structure. Logic for admin pages, AJAX, actions, and settings is now handled by dedicated classes, making the plugin more stable, performant, and easier to maintain and extend in the future.\u003Cbr \u002F>\n*   \u003Cstrong>Advanced IP Spoofing Protection.\u003C\u002Fstrong> A zero-trust “Trusted Proxies” system ensures the plugin always identifies the true visitor IP, even behind complex setups like Cloudflare or a custom reverse proxy. It neutralizes attacks that attempt to fake their IP, preventing block evasion and the framing of innocent users.\u003Cbr \u002F>\n*   \u003Cstrong>Geo-Challenge.\u003C\u002Fstrong> A smarter way to handle traffic from high-risk countries. Instead of a hard block, it presents a quick, invisible JavaScript challenge that stops bots but is seamless for human visitors. This reduces unwanted traffic without affecting potential legitimate users.\u003Cbr \u002F>\n*   \u003Cstrong>ENHANCEMENT: Full Bulk-Action Support.\u003C\u002Fstrong> IP management is now faster than ever. Both the Whitelist and the Blocked IPs list now support full bulk actions, allowing you to select and remove multiple entries at once, or unblock all IPs with a single click.\u003Cbr \u002F>\n*   \u003Cstrong>Endpoint Lockdown Mode:\u003C\u002Fstrong> Automatically shields \u003Ccode>wp-login.php\u003C\u002Fcode> and \u003Ccode>xmlrpc.php\u003C\u002Fcode> with a JavaScript challenge during sustained distributed attacks, preventing server overload.\u003Cbr \u002F>\n*   \u003Cstrong>Two-Factor Authentication (2FA):\u003C\u002Fstrong> Secure user accounts with industry-standard TOTP authentication, backup codes, role enforcement, and a central admin management dashboard.\u003Cbr \u002F>\n*   \u003Cstrong>IP Trust & Threat Scoring System:\u003C\u002Fstrong> An intelligent defense that assigns “threat points” to IPs for malicious actions, blocking them only when they reach a configurable score. More accurate and context-aware than simple rules.\u003Cbr \u002F>\n*   \u003Cstrong>Attack Signature Engine:\u003C\u002Fstrong> Proactively stops distributed botnet attacks by identifying and blocking the attacker’s “fingerprint” (signature) instead of just individual IPs.\u003Cbr \u002F>\n*   \u003Cstrong>Web Application Firewall (WAF):\u003C\u002Fstrong> Block malicious requests (SQLi, XSS, etc.) with a customizable ruleset.\u003Cbr \u002F>\n*   \u003Cstrong>And much more:\u003C\u002Fstrong> Rate Limiting, Country & ASN Blocking (with Spamhaus support), ASN Whitelisting, Push Notifications, Google reCAPTCHA, Honeypots, Active User Session Management, and Full WP-CLI Support.\u003C\u002Fp>\n","A complete WordPress security firewall: blocks IPs, bots, countries & ASN. Includes an intelligent WAF, Threat Scoring, Geo-Challenge, and 2FA.",60837,23,"2026-07-22T07:28:00.000Z","7.0.2","5.9","8.1",[73,74,75,24,76],"2fa","firewall","geoblocking","waf","https:\u002F\u002Fadvaipbl.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadvanced-ip-blocker.8.11.10.zip",97,"2026-05-28 00:00:00",{"slug":82,"name":83,"version":84,"author":85,"author_profile":86,"description":87,"short_description":88,"active_installs":89,"downloaded":90,"rating":91,"num_ratings":32,"last_updated":92,"tested_up_to":69,"requires_at_least":93,"requires_php":18,"tags":94,"homepage":97,"download_link":98,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"cloudguard","CloudGuard","1.4.6","pipdig","https:\u002F\u002Fprofiles.wordpress.org\u002Fpipdig\u002F","\u003Cp>Use the power of the cloud and a global CDN to restrict access to your login page.\u003C\u002Fp>\n\u003Cp>CloudGuard brings global and cloud driven protection to your login page. Using Cloudflare’s free Geolocation service, this super lightweight plugin restricts access to your login page, allowing access to only your chosen countries.  This means that any login attempts from the rest of the world will be automatically blocked.\u003C\u002Fp>\n\u003Cp>Additionally, this plugin tracks any unauthorized login attempts and displays them on a \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcloudguard\u002Fscreenshots\u002F\" rel=\"ugc\">world map\u003C\u002Fa> in your dashboard.\u003C\u002Fp>\n\u003Ch3>Main Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Protect your login page globally.\u003C\u002Fli>\n\u003Cli>Reduce server load.\u003C\u002Fli>\n\u003Cli>Country based IP ranges constantly updated by Cloudflare.\u003C\u002Fli>\n\u003Cli>Monitor login attempts via your dashboard.\u003C\u002Fli>\n\u003Cli>Block access to the login page or redirect to a URL.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Why Cloudflare’s Geolocation?\u003C\u002Fh3>\n\u003Cp>There are other plugins which can \u003Cstrong>restrict your login page by geographic location\u003C\u002Fstrong>. However, these plugins use your server to detect the IP and compare this to a geographic location. This adds extra overhead to your site, takes up space on your server, and requires frequent updates to keep the IP list relevant.\u003C\u002Fp>\n\u003Cp>CloudGuard is different. Since we leverage Cloudflare’s geolocation service, your server simply has to read the data, rather than compute and store it locally. Cloudflare does the grunt work, leaving your site safe, secure and optimized.\u003C\u002Fp>\n\u003Cp>Note: This plugin requires that you have an account (including the free option) on \u003Ca href=\"https:\u002F\u002Fwww.cloudflare.com\" rel=\"nofollow ugc\">Cloudflare\u003C\u002Fa> with \u003Ca href=\"https:\u002F\u002Fsupport.cloudflare.com\u002Fhc\u002Fen-us\u002Farticles\u002F200168236-What-does-Cloudflare-IP-Geolocation-do-\" rel=\"nofollow ugc\">Geolocation\u003C\u002Fa> enabled.\u003C\u002Fp>\n\u003Cp>This free plugin is brought to you by \u003Ca href=\"https:\u002F\u002Fwww.pipdig.co\u002F\" rel=\"nofollow ugc\">pipdig\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Please consider \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fview\u002Fplugin-reviews\u002Fcloudguard?rate=5#postform\" rel=\"ugc\">leaving a 5-star rating\u003C\u002Fa> if this plugin has helped you.\u003C\u002Fp>\n","Use Cloudflare's free geolocation service to restrict access to your site's login page.",1000,29501,98,"2026-05-30T18:16:00.000Z","4.9",[21,52,95,96,24],"ip","login","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcloudguard\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcloudguard.zip",{"slug":100,"name":101,"version":102,"author":101,"author_profile":103,"description":104,"short_description":105,"active_installs":13,"downloaded":106,"rating":107,"num_ratings":108,"last_updated":109,"tested_up_to":110,"requires_at_least":111,"requires_php":18,"tags":112,"homepage":118,"download_link":119,"security_score":120,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"ip-address-approval","IP Address Approval","1.9.2","https:\u002F\u002Fprofiles.wordpress.org\u002Fipapproval\u002F","\u003Cp>The IP Address Approval system provides an easy way for you to Allow or Block access to your website to protect your site from unwanted visitors. You can use the IP Address Approval system on both Internet(public) websites and Intranet(private network) websites. This super easy to use editor gives you all the control you need without the hassle of having to write your own code.\u003C\u002Fp>\n\u003Ch4>Free Version:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Block IP Addresses\u003C\u002Fli>\n\u003Cli>Block IP Address Ranges\u003C\u002Fli>\n\u003Cli>Restrict Access on ALL Pages\u003C\u002Fli>\n\u003Cli>Restrict Access on ALL Post Pages\u003C\u002Fli>\n\u003Cli>Sites Covered: Use on 1 website\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Pro Version:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Block IP Addresses and IP Address Ranges\u003C\u002Fli>\n\u003Cli>Open or Close your website\u003C\u002Fli>\n\u003Cli>If your website is ‘closed’ you can remain Open for IP Addresses and IP Address Ranges\u003C\u002Fli>\n\u003Cli>Geo Locations: Use Geo Locations to allow or block access to your website.\u003C\u002Fli>\n\u003Cli>Site Visits: View the IP Address, User Agent, the Page Visited and Time of the Visit. \u003C\u002Fli>\n\u003Cli>Manage Site Visitors Log results\u003C\u002Fli>\n\u003Cli>Block Proxy, VPN or Tor visitor connections\u003C\u002Fli>\n\u003Cli>Redirect Proxy, VPN or Tor page\u003C\u002Fli>\n\u003Cli>Block Hosting or Data Center visitor connections\u003C\u002Fli>\n\u003Cli>Redirect Hosting or Data Center page\u003C\u002Fli>\n\u003Cli>Manage Multiple Websites\u003C\u002Fli>\n\u003Cli>Restrict Access on ALL Pages\u003C\u002Fli>\n\u003Cli>Restrict Access on ALL Post Pages\u003C\u002Fli>\n\u003Cli>Restrict Access on the Admin Login Page \u003C\u002Fli>\n\u003Cli>Sites Covered: Add the IP Approval service to up to 10 websites.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Arbitrary Section\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Please Note:\u003C\u002Fstrong> You need to Create a User Account on our website \u003Ca href=\"https:\u002F\u002Fwww.ip-approval.com\" rel=\"nofollow ugc\">https:\u002F\u002Fwww.ip-approval.com\u003C\u002Fa>, and add your IP Approval Credentials to the Plugin, before it will work. This is done by an API (application program interface) to connect this plugin to our server at \u003Ca href=\"https:\u002F\u002Fwww.ip-approval.com\" rel=\"nofollow ugc\">https:\u002F\u002Fwww.ip-approval.com\u003C\u002Fa>. This is required.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Information we log in our database\u003C\u002Fstrong>\u003Cbr \u002F>\n– Blog Owners Name\u003Cbr \u002F>\n– Username\u003Cbr \u002F>\n– Email\u003Cbr \u002F>\n– Blog ID\u003Cbr \u002F>\n– Domain URL\u003Cbr \u002F>\n– Current Theme Name\u003Cbr \u002F>\n– WordPress Version\u003Cbr \u002F>\n– Plugin Version\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Explicit and Authorized Consent;\u003C\u002Fstrong> By clicking the ‘Connect Account’ button on the IP Approval Credentials tab you explicitly agree to provide the Blog Owners Name, Username, Email, Blog ID, Current Theme Name, WordPress Version and Plugin Version to the IP Address Approval service. Note that this helps us troubleshoot any issues you may encounter, as well as verifying the API Connection.\u003Cbr \u002F>\nTo learn about our privacy policy, please visit: \u003Ca href=\"https:\u002F\u002Fwww.ip-approval.com\u002Fprivacy-policy\" rel=\"nofollow ugc\">https:\u002F\u002Fwww.ip-approval.com\u002Fprivacy-policy\u003C\u002Fa>\u003C\u002Fp>\n","The IP Address Approval system provides an easy way for you to Allow or Block access to your website to protect your site from unwanted visitors.",8146,74,3,"2025-06-11T11:25:00.000Z","6.8.6","4.6",[113,114,115,116,117],"geo-location","geo-redirect","geo-security","ip-blocker","stop-spam","https:\u002F\u002Fwww.ip-approval.com\u002Fwordpress\u002Fip-approval\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fip-address-approval.1.9.2.zip",92,{"slug":122,"name":123,"version":124,"author":125,"author_profile":126,"description":127,"short_description":128,"active_installs":13,"downloaded":129,"rating":130,"num_ratings":46,"last_updated":131,"tested_up_to":132,"requires_at_least":111,"requires_php":133,"tags":134,"homepage":136,"download_link":137,"security_score":138,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"wp-cloudflare-geoip-redirect","WP Cloudflare GeoIP Redirect","1.4","webinvaders","https:\u002F\u002Fprofiles.wordpress.org\u002Fwebinvaders\u002F","\u003Cp>WP Cloudflare GeoIP Redirect plugin enables you to setup redirect for users from selected countries to specific URL.\u003C\u002Fp>\n\u003Cp>Geolocation is done using Cloudflare IP Geolocation data.\u003C\u002Fp>\n\u003Cp>Redirection is done using the php header() function and you can choose Temporary Redirect (307) or Moved Permanently (301).\u003C\u002Fp>\n\u003Cp>In order to use this plugin you need to setup Cloudflare for your website and enable Cloudflare IP Geolocation service. More info in FAQ.\u003C\u002Fp>\n","Easily setup redirect for visitors\u002Fusers from selected countries to specific URL utilizing Cloudflare IP Geolocation.",6162,86,"2021-04-22T21:22:00.000Z","5.7.15","5.2.4",[21,135,52,23],"geoip","https:\u002F\u002Fwebinvade.rs\u002Fwordpress-plugins\u002Fwp-cloudflare-geoip-redirect\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-cloudflare-geoip-redirect.zip",85,{"error":140,"url":141,"statusCode":142,"statusMessage":143,"message":143},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fganava-location-access-control\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":14,"versions":145},[146],{"version":6,"download_url":25,"svn_tag_url":147,"released_at":26,"has_diff":148,"diff_files_changed":149,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":150,"is_current":140},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fganava-location-access-control\u002Ftags\u002F1.0.0\u002F",false,[],[]]